Treasury Secretary Scott Bessent, one of the most consequential economic officials in the Trump administration, delivered a blunt warning this week that the United States government may impose sanctions on Chinese AI companies accused of stealing intellectual property from American competitors — reframing a technical debate about model training as a matter of national economic security.
The Context
The backdrop to Bessent’s remarks is a months-long controversy over a technique known as model distillation — a process in which a smaller or newer AI model is trained using outputs generated by a more capable, often proprietary, model. Done legitimately, distillation is a well-established machine learning practice. Done without authorization — by circumventing access controls and using another company’s model at scale to train a rival system — it crosses into what most legal and technical experts would characterize as a misappropriation of intellectual property, if not outright theft.
The controversy became commercially significant when Moonshot AI’s Kimi K3 model upended the generative AI competitive landscape, posting benchmark scores on coding and reasoning tasks that rival or exceed those of Anthropic’s frontier model and OpenAI’s GPT-5.6-Sol — both proprietary, subscription-gated systems. Moonshot has committed to releasing Kimi K3’s full weights on July 27, making it freely downloadable and modifiable, a move that has rattled the US AI establishment.
Anthropic had already raised the alarm directly. The company publicly stated that Chinese AI companies — including Moonshot AI, the maker of Kimi K3, as well as Minimax and DeepSeek — had accessed its Claude model “at scale while evading detection” and used that access to conduct training runs that violated its terms of service. The charge was pointed and specific: these firms weren’t just inspired by American research; they allegedly used American AI infrastructure as raw material for competing systems. The broader US-China AI competition has now acquired a legal and law-enforcement dimension it previously lacked.
The Move
Speaking on Fox Business on Tuesday, Bessent became the highest-ranking US official to publicly signal that the government is actively investigating whether Chinese open-source AI models were built on stolen American intellectual property. His language was notable for its deliberate accessibility: “There’s a very technical AI word for it called distillation, but you and I would call it theft,” he said. The translation was intentional — designed to make a complex technical argument legible to a political and public audience unfamiliar with gradient descent or training pipelines.
Bessent was explicit about the mechanism of enforcement: sanctions. “If we see, especially that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft,” he said. He also described the emergence of what amounts to forensic evidence — watermarks from US large language models reportedly appearing inside Chinese model outputs. “We are finding watermarks of our US large language models on many Chinese models, and that’s unacceptable,” Bessent said, without identifying the specific models or the methodology used to detect those watermarks.
Critically, Bessent stopped short of naming specific companies, a deliberate restraint that signals an investigation is ongoing rather than concluded. He was also careful to draw a distinction: the administration is not opposed to open-source AI in principle. He named Meta, Nvidia, and Reflection AI as examples of US companies pursuing open-source strategies the administration considers legitimate.
The Stakeholders
Anthropic
Bessent’s remarks amount to a de facto endorsement of Anthropic’s position — even without naming the company. Anthropic has been the most vocal American AI lab in accusing Chinese competitors of distillation-based IP theft, and it now has the backing of the Treasury Department’s public attention, if not yet formal legal action. That is a significant shift in Anthropic’s leverage. The company, however, faces its own credibility challenge: critics have noted that Anthropic’s own models were trained on copyrighted materials that authors and media organizations have claimed were used without permission — a tension Bessent did not address, but which will complicate any enforcement narrative.
OpenAI and the White House
The political dynamics inside the AI policy conversation are notably tangled. Dean Ball, who until recently served as a senior AI advisor to President Trump and has since become OpenAI’s head of strategy, drew fierce criticism this week after suggesting the White House might use “fear, uncertainty, and doubt” — FUD — to discourage the private sector from deploying Chinese open-source models. The backlash was immediate, with critics arguing the approach amounted to regulatory capture dressed up as national security. Ball’s move from government to OpenAI gives that criticism additional bite.
Moonshot AI and DeepSeek
The companies most directly implicated — Moonshot AI, DeepSeek, and Minimax — have not publicly responded to the specific distillation allegations in a way that has satisfied their critics. Moonshot’s Kimi K3, benchmarked against leading frontier models, is now at the center of a geopolitical dispute as much as a technical one. Beijing and Washington have both signalled interest in AI governance frameworks, but on terms that remain fundamentally incompatible. Whether Moonshot has the institutional standing or legal exposure in US jurisdictions to be meaningfully affected by sanctions remains an open question.
The Open-Source Community and Investors
Veteran tech investor Bill Gurley published an op-ed in The Washington Post arguing that open-source AI models represent one of the few viable paths to preventing an AI duopoly dominated by Anthropic and OpenAI. His argument is structurally sound: if the US government restricts or sanctions the most competitive open-source models on IP grounds, it may entrench the very incumbents whose rent-seeking it would otherwise oppose. That tension — between protecting American IP and preserving open competition — sits at the heart of the policy dilemma Bessent’s remarks have crystallized.
There is a deeper irony embedded in the distillation dispute that neither Bessent nor Anthropic have fully confronted: the same commercial logic that makes distillation attractive to Chinese competitors — access to powerful model outputs at low marginal cost — also describes how much of the US AI ecosystem was built atop scraped, unlicensed internet data. If Washington moves to sanction Chinese firms for IP violations in AI training, it will face immediate pressure to define what counts as legitimate use of third-party data, a definition that could prove as uncomfortable for American AI labs as for their Chinese counterparts. The enforcement framework being contemplated may, in practice, be impossible to apply selectively.
Chinese open-source AI is gaining power — and geopolitical risk
Moonshot’s Kimi K3, Meta’s Llama series, and DeepSeek’s models represent three different versions of the open-source AI race. Kimi K3 and DeepSeek both originate from China, while Llama is developed by Meta in the United States. Meta’s Llama and DeepSeek already have publicly available open weights, while Kimi K3’s open release was scheduled for July 27, 2025. On performance, Kimi K3 has been reported at or above Anthropic Claude and GPT-5.6-Sol on coding tasks, DeepSeek has shown strong reasoning benchmarks, and Meta’s Llama remains competitive at its parameter scale, though generally below frontier proprietary models. The biggest difference lies in legal and geopolitical risk. Anthropic has named both Kimi K3 and DeepSeek in allegations related to distillation or IP concerns, while Meta faces broader copyright lawsuits over training data but has not been accused of distillation theft in this comparison. U.S. officials have treated Meta’s Llama as a legitimate open-source model, while Kimi K3 and DeepSeek face higher scrutiny, possible sanctions, and broader export-control debate. Overall, the comparison shows that Chinese open-source models may be gaining on performance and adoption, but they carry significantly higher geopolitical and regulatory risk than U.S.-based open-weight alternatives such as Llama.
What to Watch
The most immediate question is whether Bessent’s remarks remain a rhetorical signal or harden into formal action. The administration’s use of the word “sanctions” is significant — Treasury, through the Office of Foreign Assets Control (OFAC), has broad authority to designate foreign entities and restrict their access to US markets and infrastructure. Whether that authority will be invoked against AI companies, and on what evidentiary basis, remains to be seen.
Separately, the watermark claim deserves scrutiny. If the US government has a reliable technical methodology for detecting the presence of American LLM outputs inside Chinese model weights, that would represent a meaningful forensic capability — and a potential template for broader enforcement. It would also raise immediate questions about who conducted the analysis, what peer review it has received, and whether it would hold up in any legal proceeding.
The open-source AI community will be watching closely to see whether the policy framework being discussed targets only Chinese firms or whether it establishes principles — around training data provenance, distillation restrictions, and ToS enforcement — that apply universally. If it does, American labs including Meta could face scrutiny over their own training methodologies. The risks from agentic AI systems that operate at scale without oversight compound the governance challenge: enforcement in a world of widely distributed model weights is structurally different from enforcement against centralized API providers.
Meanwhile, Moonshot AI’s planned July 27 weight release creates a natural deadline. Once Kimi K3’s weights are public, any sanctions would need to address the reality that the model will already be distributed globally — including, almost certainly, on US servers. The logistical and legal complexity of that scenario has no obvious precedent.
What This Means for the Industry
If the Trump administration follows through on Bessent’s threat, it would mark the first time the United States has used financial sanctions as a tool of AI IP enforcement — a precedent with consequences well beyond the current dispute. It would signal to every AI developer outside the United States that training methodology, data sourcing, and API access policies are no longer purely technical or commercial questions but potential triggers for geopolitical retaliation.
For Anthropic and OpenAI, the immediate effect may be welcome: a government willing to protect their IP is a government implicitly underwriting their market position. But the longer arc is more complicated. As enterprise AI buyers grow more cautious about vendor lock-in and data sovereignty, any perception that the leading US AI labs are being insulated from competition by regulatory fiat — rather than winning on merit — will accelerate demand for genuine open alternatives, whether from Meta, from European developers, or eventually from Chinese firms operating under different legal structures.
Meta, which Bessent explicitly named as a legitimate open-source actor, finds itself in an unexpectedly favourable political position: the administration’s framing implicitly endorses its strategy at the same moment its Chinese competitors are being placed under scrutiny. Nvidia’s position is more complex — as the dominant supplier of the chips that trained every model under discussion, it has business relationships on all sides of this dispute. Any sanctions regime that targets Chinese AI companies without careful carve-outs could create secondary-market pressures that complicate Nvidia’s own export-controlled position in China.
The deepest institutional implication, however, may be for the open-source AI movement itself. Bill Gurley’s argument — that open models are a structural safeguard against monopoly — has not been answered by Bessent’s framing, only superseded by it. If the US government’s response to competitive Chinese open-source AI is restriction rather than acceleration, the outcome may be precisely the duopoly that Gurley, and many others across the political spectrum, most want to avoid. That is the tension policymakers will need to resolve, and nothing in Bessent’s remarks this week suggests they have.











